Description
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Published: 2026-06-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitHub Enterprise Server has a UI misrepresentation flaw that enables an OAuth application to obtain the manage_runners:org permission without that scope appearing on the consent screen. By creating such an application and directing a user to authorize it, an attacker can gain unintended control over an organization’s runners. This violation, classified as CWE‑451, allows the attacker to add, change, or delete runners, potentially compromising CI/CD pipelines. The issue impacts all releases before 3.22 and has been resolved in 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20.

Affected Systems

All GitHub Enterprise Server releases before version 3.22 were affected. The vulnerability was fixed in releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. Administrators should upgrade to one of these patched releases.

Risk and Exploitability

The CVSS score is 4.8, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a human victim to approve a deceptive OAuth application, typically through social engineering. The likely attack vector is inferred to be a social engineering phishing‑like attack where a user is persuaded to approve a malicious OAuth application. Once authorized, the attacker gains the ability to manage organization runners, which can be used to alter pipeline behavior and potentially disrupt CI/CD operations.

Generated by OpenCVE AI on August 2, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GitHub Enterprise Server to a patched release such as 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, or 3.16.20.
  • Revoke any OAuth tokens that include the manage_runners:org scope and audit granted tokens for unnecessary permissions.
  • Review all applications that request excessive scopes and remove any obsolete or suspicious entries.

Generated by OpenCVE AI on August 2, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17. This vulnerability was reported via the GitHub Bug Bounty program. A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
References

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Github
Github enterprise Server
Vendors & Products Github
Github enterprise Server

Tue, 30 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program. A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17. This vulnerability was reported via the GitHub Bug Bounty program.
References

Tue, 30 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Title UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Github Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published:

Updated: 2026-07-01T15:37:28.521Z

Reserved: 2026-05-20T17:12:51.109Z

Link: CVE-2026-9106

cve-icon Vulnrichment

Updated: 2026-07-01T15:37:23.482Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T21:16:30.803

Modified: 2026-07-02T15:41:11.897

Link: CVE-2026-9106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:15:13Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information